Wait! Don't Leave Without Securing Your Site
Get enterprise - grade SSL certificates at a fraction of retail prices.
Save 10% on your first order, by entering coupon code SAVE10 during checkout.

You can verify the integrity of an SSL certificate and private key pair with the OpenSSL utility and its command lines.
The process consists of four steps:
Verify the private key integrity
Run the following command:
openssl rsa -in [key-file.key] -check -noout
Here’s an example of a corrupt private key:

Other errors resulting from an altered/forged key are listed below:
If you encountered any of the above errors, your private key has been tampered with and may not work with your public key. Consider creating a new private key and requesting a replacement certificate.
Here’s an example of the private key which meets the integrity:

Verify the modulus value matching with Private Key and SSL certificate pair
If you would rather not run the commands, paste both files into the Certificate Key Matcher and read the verdict.
Note: The modulus of the private key and certificate must match exactly.
To view the certificate Modulus run the command:
openssl x509 -noout -modulus -in [certificate-file.cer]
To view the private key Modulus run the command:
openssl rsa -noout -modulus -in [key-file.key]
Encrypt with the public key from and decrypt with the private key
1. Get the public key from certificate:
openssl x509 -in [certificate-file.cer] -noout -pubkey > certificatefile.pub.cer
2. Encrypt test.txt file content using public key
Create a new file called test.txt file (you can use Notepad) with the content “message test”. Perform the following command to create an encrypted message to cipher.txt file.
openssl rsautl -encrypt -in test.txt -pubin -inkey certificatefile.pub.cer -out cipher.txt
3. Decrypt from cipher.txt using the private key
Perform the following command to decrypt cipher.txt content.
openssl rsautl -decrypt -in cipher.txt -inkey [key-file.key]
Ensure that you can decrypt your cipher.txt file content to your terminal. The output from the terminal must match the content on the test.txt file.
If the content does not match, the private key has been tampered with and may not work with your public key. Consider creating a new private key and requesting a replacement certificate. Here’s an example of a decrypted message:

4. Confirm the file integrity signed with the private key
Run the following command to sign the test.sig and test.txt file with your private key:
openssl dgst -sha256 -sign [key-file.key] -out test.sig test.txt
Now, verify the signed files with your public key extracted from step 1.
openssl dgst -sha256 -verify certificatefile.pub.cer -signature test.sig test.txt
Make sure that the output from the terminal is exactly like in the example below:

If your private key is tampered with, you will receive the following message:

In this case, you should create a new private key and request a replacement certificate.
Source: Digicert’s Knowledge Base
Copy Link
Inside your ~/public directory on your server, you might find the .well-known folder. Well-known URIs are Uniform Resource Identifiers for well-known services or information available consistently across servers at URLs.
Some servers create the .well-known folder automatically, but sometimes, you may have to add it manually. This directory acts as a web-based protocol to fetch site metadata about a host before making a request.
When ordering an SSL Certificate, you must prove domain ownership as part of DCV. If you choose the HTTP/HTTPS method, you’ll have to create the .well-known directory, the folder where you must upload a TEXT file for the CA to scan and approve your SSL request.
The file should be accessible via a live website link. After you add the validation file, the CA crawler system will scan your website and look for the file. Once it finds it, you should pass domain validation within minutes.
Copy Link
To create the well-known folder, you’ll need access to your server via an SFTP client, a web hosting control panel, or any other appropriate means. Here’s how to create the .well-known folder on the most popular platforms:
The instructions below are valid for Ubuntu, Debian, and CentOS servers.
Windows-based servers do not allow you to place a dot in a folder name, therefore you need to follow these steps:
You can create a .well-known folder in WordPress in three different ways.
We don’t recommend using a plugin as it may cause compatibility and security issues over time. Instead, use our instructions above to create the .well-known folder in cPanel, the most popular hosting panel.
If you don’t have cPanel, use an SFTP client. Connect to your server and inside your ~/public folder look for the .well-knwon directory. If it’s not there, right-click on the public folder, choose Create directory, and name the new directory .well-known.
Connect to your server via the built-in FTP client or the Command Line Interface.
You can use SSH and the Secure Copy protocol to upload the TXT file.
scp AC3E5D6I8G12935LSJEIK.txt
your_username@hostname:tld://Library/WebServer/Documents/.well-known/pki-validation
Where ‘AC3E5D6I8G12935LSJEIK.txt’ is the validation file name, ‘your_username’ is the username of your server account, ‘hostname.tld’ is your Mac OSX server hostname, and ‘/Library/WebServer/Documents/’ is the default directory of the document root folder.
For all server types, if you did everything correctly, you should be able open the following URL and see the hash code along with “comodoca.com” in any web browser:
http://mywebsite.com/.well-known/pki-validation/HashFileName.txt
Copy Link
Yes, you can look at what information your CSR includes, by using our CSR Decoder tool. It is doing a process which is opposite to encrypting it.
Copy Link
A CSR is issued immediately. It will be issued to you as soon as you fill in the SSL CSR Generator from above.
Copy Link
Whether you accidentally or purposefully enter some incorrect information while using the CSR generation tool, the CSR and the Private Key will still be issued to you immediately. However, once you use the CSR code to apply for an SSL Certificate, you may or may not be issued an SSL Certificate. It is solely at the Certificate Authority’s discretion to approve or decline your SSL Certificate issuance if you entered incorrect information about you and your company.
If you realize that you entered incorrect information while generating the CSR, you simply have to put aside, ignore or delete your existing CSR and Private Key. After that, you should generate a new CSR code (which will automatically generate a new Private Key too), using correct information about yourself and your company. Use the newer CSR when applying for an SSL Certificate, and then your newer Private Key when installing your SSL Certificate on your website and server.
Copy Link
The CSR contains the following encrypted information: your country, state, city/town, name of the organization, department from your organization, the domain name that you want the SSL Certificate to be issued for, and the email address where your CSR code and the Private Key will be sent to once they are both generated.
Copy Link
A Multi-Domain Wildcard SSL Certificate is specifically created to allow users to secure multiple domains and sub-domains using one single SSL Certificate.
NOTE #1: Any Multi-Domain Wildcard SSL Certificate should start with a non-Wildcard domain. This means that anytime you configure and request a Multi-Domain Wildcard SSL Certificate, you need to generate a CSR (Certificate Signing Request) for a single domain (such as: example.com), without any asterisk sign “*”. This is a requirement that comes from the Certificate Authorities. All the additional SANs (2nd, 3rd, 4th domains) can be Wildcard domains.
For example, a Multi-Domain Wildcard SSL Certificate that has 3 SAN (4 domains) by default, allows you to secure the following:
NOTE #2: If you add a SAN item like *.domain.com, you will protect its unlimited sub-domains but not the main domain. For example, if you want to secure secure two domains and all their sub-domains, you have to configure your SSL in the following format:
You can add sub-domains to your server and they will be covered by your Wildcard SSL Certificate automatically. You do not need to re-issue your Wildcard SSL Certificate each and every time when you add sub-domains to it. The newly added sub-domains will be automatically covered by your Wildcard SSL Certificate.
Copy Link
The “SSL Certificate” stands for “Security Socket Layers Certificate”. This protocol was created to protect data travelling between two machines through data encryption.
All the information from the Internet is basically transferred from one location to another in the form of HTTP language (Hyper Text Transfer Protocol). But HTTP by itself is unprotected and susceptible to Internet tricksters and thieves. That’s why SSL Certificates were developed to protect the information traveling on the Internet.
You may know about the SSL Certificates by some common things you see in your browser: the padlock, the “HTTPS” on the browser tab (when HTTP is being protected by SSL it inherits the letter “S”).
These are all indications that the website you are using has SSL encryption and its information is secure against cyber attacks.
Copy Link
An SSL certificate warranty is insurance which covers any damage that you may incur as a result of a data breach or hack that was caused due to a flaw in the certificate. The SSL warranties range in value from $5,000 to $1,500,000. This means that the higher value certificates come with more extensive warranties.
Copy Link